Unrated severityNVD Advisory· Published Sep 2, 2026
CVE-2026-81737
CVE-2026-81737
Description
The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.8.5
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.